URLhaus Database

You are currently viewing the URLhaus database entry for http://107.172.76.193/panel/winlogon.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2090575
URL: http://107.172.76.193/panel/winlogon.exe
URL Status:Offline
Host: 107.172.76.193
Date added:2022-03-11 17:25:05 UTC
Last online:2022-04-15 03:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2022-03-11 17:26:10 UTC to abuse{at}colocrossing[dot]com)
Takedown time:1 month, 4 days, 10 hours, 6 minutes Bad (down since 2022-04-15 03:32:26 UTC)
Tags:exe Formbook link opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-17n/aexe 3e82c81d1c6fae29050a3fafb9f3dfdc64798aecccf3229a6fb6098929158fa5n/a 
2022-03-16n/aexe c1bd0f2f3ac96d89502bb30e5397b77fd0801c400b6afe989d0b5d356b1926d0n/a Formbook
2022-03-16n/aexe 4ec973add40708a9364014593e84c5e896b8ed922b6c6a5cad412b0cffdf642en/a Formbook
2022-03-15n/aexe ad957ed8d77c42ffe8a2c29ecb0ef4533f038bb8e4252f02b3d6fefab3ce1879n/a 
2022-03-14n/aexe f5591c968452fdb7824b267a5bd64584aed4261c719ce30a958b477e1e778f8bn/aFormbook
2022-03-11n/aexe 1190df73979f3dc768713f51fcf6e2eb439b95caf7c4a2b998c377ea5a35e9d5Virustotal results 25.37%Formbook